690
VMScore

CVE-2019-12799

Published: 13/06/2019 Updated: 09/01/2024
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 690
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

In createInstanceFromNamedArguments in Shopware up to and including 5.6.x, a crafted web request can trigger a PHP object instantiation vulnerability, which can result in an arbitrary deserialization if the right class is instantiated. An attacker can leverage this deserialization to achieve remote code execution. NOTE: this issue is a bypass for a CVE-2017-18357 whitelist patch.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

shopware shopware

Vendor Advisories

Check Point Reference: CPAI-2019-3122 Date Published: 28 Nov 2023 Severity: High ...